In a well-coordinated operation, unknown attackers performed a Border Gateway Protocol (BGP) hijacking to gain control over IP addresses assigned to Softaculous, the developer of Virtualizor and a platform for installing and managing web software. The company had used those IP addresses to issue software updates and host its client and billing site. Once in control of the hijacked space, the attackers pushed malware disguised as legitimate updates to unsuspecting users.
The security breach leveraged weaknesses in Hetzner Online's routing security setup and the process for obtaining valid TLS certificates, according to a report by Ars Technica. The attack represents an unusual convergence of routing protocol exploitation and supply chain compromise, allowing the threat actors to infect networks at scale without the need for more conventional intrusion methods.
As of the report's publication, the full extent of the compromise and the identity of the attackers remain unknown. The incident highlights ongoing vulnerabilities in the Internet's core routing infrastructure, where BGP relies largely on trust rather than built-in security mechanisms.